CWE-122— Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().— MITRE CWE catalog
3,270 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-122page 5 of 66
- CVE-2024-22857CRITICALCVSS 9.8EG 9.82024-03-07
Heap based buffer flow in zlog v1.1.0 to v1.2.17 in zlog_rule_new().The size of record_name is MAXLEN_PATH(1024) + 1 but file_path may have data upto MAXLEN_CFG_LINE(MAXLEN_PATH*4) + 1. So a check was missing in zlog_rule_new() while copyi…
- CVE-2024-21795CRITICALCVSS 9.8EG 9.82024-02-20
A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can pro…
- CVE-2024-1283CRITICALCVSS 9.8EG 9.82024-02-07
Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2023-7158CRITICALCVSS 9.8EG 9.82023-12-29
A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the at…
- CVE-2023-47118CRITICALCVSS 9.8EG 9.82023-12-20
ClickHouse® is an open-source column-oriented database management system that allows generating analytical data reports in real-time. A heap buffer overflow issue was discovered in ClickHouse server. An attacker could send a specially cra…
- CVE-2023-29073CRITICALCVSS 9.8EG 9.82023-11-23
A maliciously crafted MODEL file when parsed through Autodesk AutoCAD 2024 and 2023 can be used to cause a Heap-Based Buffer Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbi…
- CVE-2023-36028CRITICALCVSS 9.8EG 9.82023-11-14
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- CVE-2023-46256CRITICALCVSS 9.8EG 9.82023-10-31
PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value checking. A malfun…
- CVE-2023-40889CRITICALCVSS 9.8EG 9.82023-08-29
A heap-based buffer overflow exists in the qr_reader_match_centers function of ZBar 0.23.90. Specially crafted QR codes may lead to information disclosure and/or arbitrary code execution. To trigger this vulnerability, an attacker can digi…
- CVE-2023-4322CRITICALCVSS 9.8EG 9.82023-08-14
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
- CVE-2022-46290CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a m…
- CVE-2022-46289CRITICALCVSS 9.8EG 9.82023-07-21
Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a m…
- CVE-2022-48512CRITICALCVSS 9.8EG 9.82023-07-06
Use After Free (UAF) vulnerability in the Vdecoderservice service. Successful exploitation of this vulnerability may cause the image decoding feature to perform abnormally.
- CVE-2023-29363CRITICALCVSS 9.8EG 9.82023-06-14
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2023-28753CRITICALCVSS 9.8EG 9.82023-05-18
netconsd prior to v0.2 was vulnerable to an integer overflow in its parse_packet function. A malicious individual could leverage this overflow to create heap memory corruption with attacker controlled data.
- CVE-2023-0854CRITICALCVSS 9.8EG 9.82023-05-11
Buffer overflow in NetBIOS QNAME registering and communication process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unrespons…
- CVE-2023-0851CRITICALCVSS 9.8EG 9.82023-05-11
Buffer overflow in CPCA Resource Download process of Office / Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arb…
- CVE-2023-24943CRITICALCVSS 9.8EG 9.82023-05-09
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
- CVE-2022-43634CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the dsi_writeinit function. The issue…
- CVE-2023-25668CRITICALCVSS 9.8EG 9.82023-03-25
TensorFlow is an open source platform for machine learning. Attackers using Tensorflow prior to 2.12.0 or 2.11.1 can access heap memory which is not in the control of user, leading to a crash or remote code execution. The fix will be inclu…
- CVE-2023-23415CRITICALCVSS 9.8EG 9.82023-03-14
Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
- CVE-2023-21692CRITICALCVSS 9.8EG 9.82023-02-14
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- CVE-2023-21690CRITICALCVSS 9.8EG 9.82023-02-14
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- CVE-2023-21689CRITICALCVSS 9.8EG 9.82023-02-14
Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
- CVE-2022-41991CRITICALCVSS 9.8EG 9.82023-01-26
A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to a heap buffer overflow. An attacker can send a networ…
- CVE-2022-41838CRITICALCVSS 9.8EG 9.82022-12-22
A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger t…
- CVE-2022-41794CRITICALCVSS 9.8EG 9.82022-12-22
A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger th…
- CVE-2022-41639CRITICALCVSS 9.8EG 9.82022-12-22
A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can resul…
- CVE-2022-3520CRITICALCVSS 9.8EG 9.82022-12-02
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
- CVE-2022-35712CRITICALCVSS 9.8EG 9.82022-10-14
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …
- CVE-2022-35711CRITICALCVSS 9.8EG 9.82022-10-14
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this …
- CVE-2022-36934CRITICALCVSS 9.8EG 9.82022-09-22
An integer overflow in WhatsApp could result in remote code execution in an established video call.
- CVE-2022-1286CRITICALCVSS 9.8EG 9.82022-04-10
heap-buffer-overflow in mrb_vm_exec in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.
- CVE-2022-1253CRITICALCVSS 9.8EG 9.82022-04-06
Heap-based Buffer Overflow in GitHub repository strukturag/libde265 prior to and including 1.0.8. The fix is established in commit 8e89fe0e175d2870c39486fdd09250b230ec10b8 but does not yet belong to an official release.
- CVE-2021-23165CRITICALCVSS 9.8EG 9.82022-03-16
A flaw was found in htmldoc before v1.9.12. Heap buffer overflow in pspdf_prepare_outpages(), in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
- CVE-2022-0631CRITICALCVSS 9.8EG 9.82022-02-18
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
- CVE-2022-0570CRITICALCVSS 9.8EG 9.82022-02-14
Heap-based Buffer Overflow in Homebrew mruby prior to 3.2.
- CVE-2022-0318CRITICALCVSS 9.8EG 9.82022-01-21
Heap-based Buffer Overflow in vim/vim prior to 8.2.
- CVE-2021-24042CRITICALCVSS 9.8EG 9.82022-01-04
The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp for iOS prior to v2.21.230, WhatsApp Business for iOS prior to v2.21.230, WhatsApp for KaiOS prior to v2.2143, WhatsApp…
- CVE-2022-0080CRITICALCVSS 9.8EG 9.82022-01-02
mruby is vulnerable to Heap-based Buffer Overflow
- CVE-2021-45956CRITICALCVSS 9.8EG 9.82022-01-01
Dnsmasq 2.86 has a heap-based buffer overflow in print_mac (called from log_packet and dhcp_reply). NOTE: the vendor's position is that CVE-2021-45951 through CVE-2021-45957 "do not represent real vulnerabilities, to the best of our knowle…
- CVE-2021-24041CRITICALCVSS 9.8EG 9.82021-12-07
A missing bounds check in image blurring code prior to WhatsApp for Android v2.21.22.7 and WhatsApp Business for Android v2.21.22.7 could have allowed an out-of-bounds write if a user sent a malicious image.
- CVE-2021-3756CRITICALCVSS 9.8EG 9.82021-10-29
libmysofa is vulnerable to Heap-based Buffer Overflow
- CVE-2021-33023CRITICALCVSS 9.8EG 9.82021-10-18
Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code.
- CVE-2021-21825CRITICALCVSS 9.8EG 9.82021-08-18
A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provi…
- CVE-2021-21810CRITICALCVSS 9.8EG 9.82021-08-17
A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specially crafted XML file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vul…
- CVE-2021-21830CRITICALCVSS 9.8EG 9.82021-08-13
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can provide a malicious file to…
- CVE-2021-21829CRITICALCVSS 9.8EG 9.82021-08-13
A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem functionality of AT&T Labs’ Xmill 0.7. A specially crafted XMI file can lead to remote code execution. An attacker can pro…
- CVE-2021-33485CRITICALCVSS 9.8EG 9.82021-08-03
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
- CVE-2021-24036CRITICALCVSS 9.8EG 9.82021-07-23
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22…
Map vulnerabilities like CWE-122 to your infrastructure
EchelonGraph correlates every CVE — across CWE-122 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →